I have been reading this forum and the tips but still have the problem here are the log you ask for ... Thanks for your help.
Malwarebytes' Anti-Malware 1.39
Database version: 2434
Windows 5.1.2600 Service Pack 3
7/15/2009 1:01:46 PM
mbam-log-2009-07-15 (13-01-46).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 207993
Time elapsed: 1 hour(s), 30 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 97
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\twain_32 (Spyware.Zbot) -> Quarantined and deleted successfully.
Files Infected:
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104822.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104829.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104836.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0105843.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0105850.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105859.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105866.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105873.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0105882.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0106888.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107888.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107901.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107908.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0107917.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108917.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108924.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108931.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0110931.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0110939.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP651\A0110974.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP651\A0111974.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP652\A0112982.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113108.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113115.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113122.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP656\A0113246.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP658\A0113316.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP658\A0113323.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0114355.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0113338.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0114346.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP660\A0114381.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114445.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114452.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114459.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP664\A0114476.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP664\A0114483.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114498.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114511.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114518.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114556.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114563.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114570.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114578.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114585.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114592.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114599.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114606.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114613.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114620.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114627.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114665.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114636.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114655.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114685.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114701.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114714.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114724.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP674\A0115566.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP679\A0116495.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP680\A0116515.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP681\A0116623.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP683\A0116646.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP683\A0116655.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP686\A0116686.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP688\A0116779.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP688\A0116788.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116800.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116819.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116827.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116836.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116844.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116857.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116864.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116872.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP691\A0116894.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP691\A0116901.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP693\A0116911.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP693\A0118019.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP694\A0118115.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP695\A0118132.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP696\A0118141.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP697\A0118157.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP697\A0118167.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP700\A0118497.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP701\A0121342.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP703\A0124232.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113279.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113286.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113293.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113300.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113307.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\1A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\servises(2).dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\servises.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\local settings\Temp\e.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\application data\twain_32\user.ds (Spyware.Zbot) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.39
Database version: 2441
Windows 5.1.2600 Service Pack 3
7/16/2009 11:29:26 AM
mbam-log-2009-07-16 (11-29-26).txt
Scan type: Quick Scan
Objects scanned: 103387
Time elapsed: 16 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:53:35 PM, on 7/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwicon2k.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.62 avremover-pro.com
O1 - Hosts: 209.44.111.62 www.avremover-pro.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKist] C:\Program Files\Digital Media Reader\shwicon2k.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [servises] C:\WINDOWS\system32\servises.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [F-PROT Antivirus Tray application] C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [servises] C:\WINDOWS\system32\servises.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-PROT Antivirus for Windows system (FPAVServer) - FRISK Software International - C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 9212 bytes
Thanks again
Malwarebytes' Anti-Malware 1.39
Database version: 2434
Windows 5.1.2600 Service Pack 3
7/15/2009 1:01:46 PM
mbam-log-2009-07-15 (13-01-46).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 207993
Time elapsed: 1 hour(s), 30 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 97
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\twain_32 (Spyware.Zbot) -> Quarantined and deleted successfully.
Files Infected:
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104822.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104829.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0104836.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0105843.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP646\A0105850.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105859.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105866.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP647\A0105873.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0105882.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0106888.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107888.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107901.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP648\A0107908.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0107917.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108917.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108924.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0108931.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0110931.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP649\A0110939.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP651\A0110974.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP651\A0111974.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP652\A0112982.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113108.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113115.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP655\A0113122.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP656\A0113246.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP658\A0113316.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP658\A0113323.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0114355.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0113338.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP659\A0114346.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP660\A0114381.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114445.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114452.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP662\A0114459.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP664\A0114476.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP664\A0114483.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114498.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114511.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP665\A0114518.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114556.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114563.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP666\A0114570.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114578.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114585.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114592.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114599.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP667\A0114606.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114613.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114620.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP668\A0114627.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114665.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114636.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114655.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP669\A0114685.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114701.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114714.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP670\A0114724.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP674\A0115566.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP679\A0116495.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP680\A0116515.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP681\A0116623.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP683\A0116646.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP683\A0116655.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP686\A0116686.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP688\A0116779.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP688\A0116788.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116800.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116819.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116827.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116836.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP689\A0116844.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116857.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116864.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP690\A0116872.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP691\A0116894.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP691\A0116901.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP693\A0116911.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP693\A0118019.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP694\A0118115.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP695\A0118132.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP696\A0118141.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP697\A0118157.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP697\A0118167.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP700\A0118497.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP701\A0121342.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP703\A0124232.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113279.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113286.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113293.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113300.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{d23eff2a-bfef-46a5-8364-d064e372df2b}\RP657\A0113307.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\1A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\servises(2).dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\servises.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\local settings\Temp\e.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\application data\twain_32\user.ds (Spyware.Zbot) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.39
Database version: 2441
Windows 5.1.2600 Service Pack 3
7/16/2009 11:29:26 AM
mbam-log-2009-07-16 (11-29-26).txt
Scan type: Quick Scan
Objects scanned: 103387
Time elapsed: 16 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:53:35 PM, on 7/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwicon2k.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.62 avremover-pro.com
O1 - Hosts: 209.44.111.62 www.avremover-pro.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKist] C:\Program Files\Digital Media Reader\shwicon2k.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [servises] C:\WINDOWS\system32\servises.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [F-PROT Antivirus Tray application] C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [servises] C:\WINDOWS\system32\servises.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-PROT Antivirus for Windows system (FPAVServer) - FRISK Software International - C:\Program Files\FRISK Software\F-PROT Antivirus for Windows\FPAVServer.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 9212 bytes
Thanks again